Reference
DNIe and e-signature glossary
Updated: 20 July 2026
The technical terms that come up when reading, signing in or signing with the DNIe, explained in a sentence or two each: signature formats, smart-card standards, and concepts specific to Spain's public administration.
DNIe
Documento Nacional de Identidad electrónico — Spain's electronic national identity document, issued by the Dirección General de la Policía. A card with a cryptographic chip holding the holder's identity data, photograph and digital certificates.
Digital certificate
A cryptographic file, issued by a certification authority, that binds a public key to an identity. The DNIe carries an authentication certificate and a signing certificate; both expire roughly every 2 years, before the physical card does. See what to do once they've expired.
PIN and PUK
The PIN is the code that unlocks the DNIe chip for reading, signing in or signing. Unlike a SIM card, the DNIe has no PUK: if the PIN is blocked after 3 failed attempts, the only way to set a new one is in person, at a PAD. Full guide: blocked or expired PIN.
PAdES
PDF Advanced Electronic Signatures. A European standard (ETSI EN 319 142) for electronically signing PDF files while preserving their original format.
CAdES
CMS Advanced Electronic Signatures. A European standard (ETSI EN 319 122) for electronically signing any file type, not just PDF, packaging the signature alongside the original document.
XAdES
XML Advanced Electronic Signatures. A European standard (ETSI EN 319 132) for signing XML documents, widely used in government filings and e-invoicing.
Timestamp (RFC 3161)
A cryptographic proof, issued by a Time Stamping Authority (TSA), that a document existed at a specific instant. Only the document's hash — its mathematical fingerprint — is sent, never its content.
OCSP
Online Certificate Status Protocol. A protocol for checking in real time whether a digital certificate has been revoked, by querying only the identifier of that certificate.
PKCS#11
A cryptographic standard defining a common interface for applications — such as browsers — to access smart cards and cryptographic tokens. Firefox on macOS needs it to recognize a card's certificates, which is why macDNIe ships its own PKCS#11 module in the direct-download edition. More in the AutoFirma on Mac guide.
PKCS#15
A standard defining how certificates, keys and data are organized and stored inside a smart card's chip, such as the DNIe's, so any compatible reader can interpret them uniformly.
CWA 14890
A European specification (CEN Workshop Agreement) defining the encrypted secure channel between a card like the DNIe and the application reading it, protecting the PIN and personal data as they travel between card and computer.
ISO/IEC 7816-4
An international standard defining the commands (APDUs) a reader uses to communicate with the chip of a contact smart card, such as the DNIe.
CCID
Chip/Smart Card Interface Device. A standard USB device class for smart-card readers, recognized natively by macOS with no extra drivers needed.
CryptoTokenKit
A macOS framework that lets Safari, Chrome and Edge natively recognize a smart card's certificates, surfacing them directly in the browser's own sign-in dialog.
PAD (DNIe Update Point)
A self-service kiosk, installed inside DNIe issuing offices (police stations), for unblocking a PIN or renewing expired certificates via fingerprint verification. Free, with no appointment needed. Full detail in blocked or expired PIN.
Sede electrónica
The official online portal of a Spanish public body — the Tax Agency, Social Security, the DGT and others — through which legally valid administrative procedures can be completed, almost always requiring sign-in with a digital certificate.
AutoFirma
The official e-signature application, distributed free of charge by the Government of Spain, which many e-government sites invoke directly from the browser to sign a submission on the spot. Full comparison: AutoFirma on Mac.
Missing a term? Write to us and we'll add it.